Why would any of the proposals provide any meaningful protection against this threat model? Maersk claims NotPetya cost them $250M to $300M [1]. Assuming a criminal organization could demonstrate to Maersk that they could do an attack with similar effects they should be able to extort Maersk for a similar amount of money. If we discount due to unknown information, ROI, etc. I think it is reasonable to say that an ext…
This is ridiculous. You're basically saying that having any security at all is pointless because someone will always still be able to break into your system in some way. Nothing could be further from the truth. Only ignorant amateurs believe that security is an all-or-nothing game. By making your system more difficult to break into, you: * increase the effort and thus cost for the attacker, thereby reducing the numbe…
To go through your arguments in order:
Increasing the effort to attack is meaningful if it reduces aggregate harm in excess of the cost of implementation. In the specific case of the NotPetya attack on Maersk and generalized to similar attacks, there is no evidence that any of the proposed measures would meaningfully reduce the probability or raise the cost to be other than extremely profitable (this is my statement that $30M cost of attack is profitable). This is because the benefit of attack is so high relative to the cost of exploit development and deployment. So, in the specific case of techniques designed to prevent large, valuable attacks, it has no significant impact since you would need to raise the cost of such an attack to around the benefit of doing such an attack.
Reducing the damage they can do would be useful. The damage done in the Maersk attack occurred over the course of a few hours at most. Any defense against such a technique would need to already be prepared or completely automated. From my reading, damage mitigation usually occurs far after and mostly only prevents the marginal long tail, so I will contend, as in my previous post, that an organization with $30M in funding would be able to do the same amount of damage to any system given that they have the element of surprise and reconnaissance.
Making yourself a less attractive target is only meaningful if nobody wants to attack in you particular, it is not easy to wantonly attack all vulnerable parties, and the attacker does not have enough resources after attacking all even more profitable targets before attacking you since, as we stated before, it is still very beneficial to attack you. For the first, that is a bad bet when running a large-scale multinational. For the second, that is literally what software is good at, mass synchronized automated attacks. NotPetya is literally an example of a wanton attack. It is mentioned in that article that Maersk was not even the target. They were accidentally attacked for $250M in damages. Being a less attractive target means nothing if somebody has a weapon that hits all attractive targets at the same time for no extra effort. And for the third, that is a terrible bet in the long run because profitable targets means they have money after each attack, so they will have money to spare to go after you. The only comfort is that it may take them time to hockey-stick to the point where they can saturate the market, but saturate they will. We are already seeing this with the increase in attacks with meaningful economic upside for the attacking parties instead of cheesy little $200/computer attacks.
Not deploying vulnerable systems is always an option, it just depends on the cost-benefit analysis as you state. My thesis is that the cost of vulnerable systems is, in the long run, significantly worse than almost all companies realize and there is no effective solution. My justification for this is that I am firmly of the belief, as my questions above indicate, that there is no company that can defend against a $30M attack and that a $30M attack can easily and credibly cause $300M in damages, and, even assuming good-faith extortion so they do not just extort for more money with the same attack, there are enough more $30M attacks that can cause $300M in damages that any such company will go bankrupt either from paying the extortion or from the extortion following through on their threats.
As a thought-experiment to go with this, if Maersk offered a $30M bounty for each unique vulnerability discovered that could cause them over $300M in damages, do you think they would run out of such bugs first or go bankrupt first? If the answer is "bugs first", why do they not offer such a bounty since each such vulnerability discovered is at least a 10:1 ROI for criminals and thus would be highly attractive to discover?
Just to get ahead of a common response to the above thought experiment corollary. Some people will respond that companies do not need to offer that much to get such vulnerabilities reported to them. This indicates that the problem is even worse than I stated since the cost of discovery is lower which means the criminal ROI is even higher. If they offered $30M for all such vulnerabilities they would be more likely to remove the highly attractive 10+:1 ROI attacks that can do tremendous amounts of damage to them which is a great ROI for the company.